Junglewise Threat Intelligence

CVE-2026-1709: Keylime authentication bypass in registrar component

CVE-2026-1709 · Severity: critical · CVSS 9.4 · Published 2026-02-06

Technologies: keylime (PyPI), Red Hat Corportation Enterprise Linux. Vendors: PyPI.

Executive brief

Keylime, a security tool used to verify the integrity of remote computers using hardware-based trust, contains a flaw where it fails to properly check the identity of connecting clients. This allows an unauthorized person on the network to bypass security controls and perform administrative tasks, such as deleting registered devices or accessing sensitive hardware security data. This could lead to a loss of trust in the monitored infrastructure or a disruption of security monitoring services.

Technical details

An authentication bypass vulnerability exists in the Keylime registrar component starting with version 7.12.0. The root cause is the failure to enforce client-side Transport Layer Security (TLS) authentication, which is intended to verify the identity of connecting clients via certificates. A remote, unauthenticated attacker can connect to the registrar without presenting a valid client certificate to perform administrative actions such as listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents. Red Hat has released security updates for Enterprise Linux 9 and 10 to address this issue.

Affected products

  • Keylime Project Keylime >= 7.12.0, < 7.12.1-11.el9_7.4 (RHEL 9), < 7.12.1-11.el10_1.4 (RHEL 10)
  • Red Hat Corportation Enterprise Linux 9, 10

Timeline

  • 2026-02-06: disclosed
  • 2026-02-09: patched: Red Hat released security updates RHSA-2026:2224 and RHSA-2026:2225

References

Related threats